arXiv:2510.12233cs.LG2025-10

提出可解释的多维度攻击框架,揭示图-语言模型在结构与文本上的脆弱性。

Unveiling the Vulnerability of Graph-LLMs: An Interpretable Multi-Dimensional Adversarial Attack on TAGs

  • 设计三模块协同攻击框架,同时扰动图结构与文本特征。
  • 在多个数据集上实现更高攻击成功率与隐蔽性,优于现有方法。
  • 适合安全研究者与模型鲁棒性提升者参考,推动图神经网络防御发展。

图神经网络(GNN)已成为建模图结构数据的核心框架,广泛应用于社交网络分析、分子化学等领域。通过融合大语言模型(LLM),文本属性图(TAGs)借助丰富的文本语义增强节点表征,显著提升图学习的表达能力。然而,这种复杂结合也引入了关键安全隐患:图-语言模型在图结构拓扑和文本属性上均易受对抗攻击。尽管已有针对各方面的专用攻击方法,但尚无统一框架。本文提出可解释的多维度图攻击(IMDGA),一种以人为中心的对抗攻击框架,能协同实施结构与文本层面的扰动。IMDGA包含三个紧密集成模块,兼顾攻击可解释性与破坏力。通过严格的理论分析与跨数据集、多架构的实证评估,IMDGA在可解释性、攻击效果、隐蔽性与鲁棒性方面均优于现有方法。本工作揭示了图-语言模型在语义层面的未被充分关注的脆弱性,为提升其抗攻击能力提供重要洞见。代码与资源已公开于 https://anonymous.4open.science/r/IMDGA-7289。

原文摘要 · Abstract (English)

Graph Neural Networks (GNNs) have become a pivotal framework for modeling graph-structured data, enabling a wide range of applications from social network analysis to molecular chemistry. By integrating large language models (LLMs), text-attributed graphs (TAGs) enhance node representations with rich textual semantics, significantly boosting the expressive power of graph-based learning. However, this sophisticated synergy introduces critical vulnerabilities, as Graph-LLMs are susceptible to adversarial attacks on both their structural topology and textual attributes. Although specialized attack methods have been designed for each of these aspects, no work has yet unified them into a comprehensive approach. In this work, we propose the Interpretable Multi-Dimensional Graph Attack (IMDGA), a novel human-centric adversarial attack framework designed to orchestrate multi-level perturbations across both graph structure and textual features. IMDGA utilizes three tightly integrated modules to craft attacks that balance interpretability and impact, enabling a deeper understanding of Graph-LLM vulnerabilities. Through rigorous theoretical analysis and comprehensive empirical evaluations on diverse datasets and architectures, IMDGA demonstrates superior interpretability, attack effectiveness, stealthiness, and robustness compared to existing methods. By exposing critical weaknesses in TAG representation learning, this work uncovers a previously underexplored semantic dimension of vulnerability in Graph-LLMs, offering valuable insights for improving their resilience. Our code and resources are publicly available at https://anonymous.4open.science/r/IMDGA-7289.

图神经网络对抗攻击可解释性文本属性图

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。